8 ms·
Gocker: Docker implemented in 1.3k lines of Go
- javajosh 6y agoHas anyone made an "X implemented in N lines of Y" site yet?
- grogenaut 6y agoHow many lines of code can you make it in?
- Skunkleton 6y ago> How many lines of code can you make it in? xinylines.io - implemented in zero lines of code, and one large shameful html file.
- faceplanted 6y agoSounds like your next project bro Or a subreddit, whatevs.
- yjftsjthsd-h 6y agoLOL, obviously the first entry should be "XinNlinesofY implemented in 1000 lines of Go!"
- xtony 6y agoBy that logic, Hacker News should've been a subreddit too.
- emmanueloga_ 6y agoNot exactly the same, but there's [1] and [2]. 1: http://aosabook.org/ http://aosabook.org/ 2: https://github.com/danistefanovic/build-your-own-x https://github.com/danistefanovic/build-your-own-x
- fartcannon 6y agoRosettacode is a bit like that. Youd have to do your own line count, though.
- monocasa 6y ago500 Lines or Less is a great book in that genre. https://github.com/aosabook/500lines/ https://github.com/aosabook/500lines/
- miked85 6y agoIsn’t Docker implemented in Go already?
- thephyber 6y agoYes. TIL. > What Programming Language Does Docker Use? Docker is written in the Google Go (golang) programming language. To learn why Go was used, we’ll refer you directly to Google.[1] [1] https://blog.stoneriverelearning.com/docker-101-what-is-docker-and-how-does-it-work/ https://blog.stoneriverelearning.com/docker-101-what-is-dock...
- birdyrooster 6y agoDoesn't matter, rewrite it and make the name a gortmanteau.
- dvtrn 6y agogortmanteau Sir we need you to come with us.
- rantwasp 6y agotake your upvote and get out :))
- stock_toaster 6y agoI think you mean, take your upvote and go. ;)
- rantwasp 6y agotake your upvote, check err and go.
- donio 6y ago...and it was probably around 1.5K lines early in its life. But that misses the point. This is very helpful for understanding how a Docker-like system works since it's a small and mostly self-contained implementation. You can read through the entire thing and fully understand it. It only cheats in the container registry handling where it pulls in github.com/google/go-containerregistry and for the network setup where it uses github.com/vishvananda/netlink. The rest is done in terms of Go stdlib and syscalls. Early Docker used external utilities (lxc, iptables) and had the client/server stuff already so it's not as straightforward.
- i_have_to_speak 6y agoHere's one in 100 lines of bash called, what else, "bocker": https://github.com/p8952/bocker https://github.com/p8952/bocker
- phinnaeus 6y agoprevious discussion: https://news.ycombinator.com/item?id=22244706 https://news.ycombinator.com/item?id=22244706
- D2187645 6y agoNow someone make one for fortran
- grensley 6y agoHonestly, I don't like lines of code as a metric for anything over the novelty amount of 1. And even then, that's usually some demonic Python list comprehension code. That being said, the code here is pretty approachable and they weren't noticeably trying to cram it into fewer lines. Like the library, not this marketing.
- Frost1x 6y agoWhile I tend to agree, I think LoC can give a sense of scale for large systems and at least a tiny bit of insight about its potential complexity. I recently worked with a client on an integration effort that had to touch many different points on a (massive, for me) codebase with tens of millions of LoC. For that, LoC was the only reasonable metric I could come up with to try and convey the scale and complexity of the task at hand--being quite ignorant of the system's (and subsystems') architecture(s) at the time. That was further complicated by the way the massive codebase supported all sorts of dynamic compositions and certain interactions needed to work with baseline compositions expressed in a form of markup totaling about about 5 times the amount of the actual code base, amongst other things. These folks thought the integration could be done for $80k tops and in a couple months. It took LoC metrics to get them to understand the potential complexity at hand and that a lot more time needed to be spent in assessment and design before jumping in.
- nemosaltat 6y agoHopefully you’ll forgive this potentially obvious question- is LoC (still?) generally accepted to be bounded ar 80 col?
- 0xEFF 6y agoIn some circles yes. Linus recently weighed in against the 80 limit. http://lkml.iu.edu/hypermail/linux/kernel/2005.3/08168.html http://lkml.iu.edu/hypermail/linux/kernel/2005.3/08168.html
- awirth 6y agoI assume you probably can't share the client, but can you share the general domain of the software?
- Proven 6y agoNot in Rust? Wow.
- pbreit 6y agoCan someone explain the value/purpose of docker to someone who (easily) deploys regular apps to a Digital Ocean droplet?
- gitgud 6y agoReproducibility is the biggest value in my opinion. A Dockerfile encapsulates all the messy dependencies in a single isolated environment. This also makes deployments easier too.
- laingc 6y agoI would say that's portability rather than reproducibility. Docker increases the extent of, but doesn't guarantee, reproducibility.
- harpratap 6y agoIn which case does it not guarantee reproducibility?
- fomojola 6y agoI can answer this one. Sometimes you have lines like this: FROM ubuntu:focal RUN apt-get -y install libssl-dev <your app details> Since libssl-dev gets periodically updated (security updates and whatnot) if you build this now and build it again in 1 year you're very probably not going to get the same OpenSSL version. So it MIGHT be reproducible, but can easily give you different results depending on updates to the packages and the way your Dockerfile imports external dependencies. And that's before we even mention updates to the base container image. Of course, you can refer to a specific container image id and pin all your packages, which would go a long way to improving reproducibility.
- harpratap 6y agoSo it's wrong (or rather uninformed) usage of Docker that leads to this, the tech itself is sound and does guarantee reproducibility.
- gorgoiler 6y agoVery nice! I love projects like this that return to first principles, and rebuild the core without the cruft. It is refreshing. The dependency on netlink adds a little to the code weight. Some of this also feels like it could just be a shell script (sh, unlike Go, ships with built in Linux support for netlink, and sticks with dotted-quad-string types for IP addresses instead of mixing with int32!) I did not realize cgroups were this simple to manipulate. Thank you for the enlightenment.
- nine_k 6y agoTBH, all network utilities I ever saw accept the int32 form of IP addresses. E.g. ping 127.0.0.1 can also be written as ping 0x7f000001 Try it; it works.
- arpa 6y agoYou can also just provide an integer. That works too.
- Erwin 6y agoURLs too, though Chrome makes them canonical: http://0xacd91124/ http://0xacd91124/ -- Google I did a quick search for whether "fun" Hex strings are reachable, but didn't find any (e.g. the canonical http://0xcafebabe http://0xcafebabe). Random combination of hex-words are login pages to web cameras or cable modems. I didn't try to e.g. replace "e" with "3", e.g. http://0xcaf3babe/ http://0xcaf3babe/
- forty 6y agoThe HN title is not great. It's not docker, it's a mini-docker as the original title says. For example there is no "gocker build" command. I wonder if that can run in unprivileged docker.
- jraph 6y agoMy 2018 joke has been implemented. > Or Gocker, an implementation of Docker in go... https://news.ycombinator.com/item?id=16119842 https://news.ycombinator.com/item?id=16119842
- toyg 6y agoLol. Should link the root though, plenty of suggestions for others: https://news.ycombinator.com/item?id=16117172 https://news.ycombinator.com/item?id=16117172
- larntz 6y agoAnd no one thought of Focker written in F#?
- Tade0 6y agoAs a kid I was a compulsive liar and would make up non-existent stories. With the advent of search engines I discovered that any story I can come up with actually happened somewhere in the world and has an article about it already.
- OzzyB 6y ago
- kohtatsu 6y agoThis talk by Bryan Cantrill on the history of OS-level virtualization is great. https://youtu.be/hgN8pCMLI2U https://youtu.be/hgN8pCMLI2U Apparently the first version of Jails was a few hundred lines of code.
- drej 6y agoCheck out this Liz Rice talk on implementing container tech from scratch. Very clear. https://www.youtube.com/watch?v=8fi7uSYlOdc https://www.youtube.com/watch?v=8fi7uSYlOdc
- koffiezet 6y agoPretty cool, and very educational for people not familiar with how these things work That said (and I've said this before), this is not really Docker. It's running containers, not the same thing. If you want to compare it to anything, it's runc, but that's not a good headline :) Not that the docker architecture is that clean, but it is the combination of ideas it brought to the table what made docker docker: - have APIs to do everything, from launching workloads to building images. - combining layered filesystems with os-level namespaces - package format for "images" coupled with a distribution system If it was just starting containers, that was already possible for a good while (and many shared hosting providers already did this). I think many people underestimate the importance of the first point, having an API to do all this. It's having this combination of ideas that democratised cloud computing, it is what makes the bigger picture possible. While the Docker API is currently not very important anymore, it showed the possibilities, and made the limitations it had also very apparent, and at the beginning, nobody had solutions for this. It took things like Mesos and kubernetes to take it to the next level, with the latter having become the de-facto standard container API.
- notrandom 6y ago> If you want to compare it to anything, it's runc, but that's not a good headline :) I don’t know, gunc is a pretty good name.
- lima 6y agoCool educational project! runc - which is the low-component that does the actual container launching in Docker and other runtimes - is mostly written in Go and quite approachable[1], if you're curious what a production-ready container runtime looks like. Namespaces look simple on the surface, but there are plenty of subleties, particularly when using Go: - `runtime.LockOSThread()` has to be called before entering a namespace to pin the goroutine to a specific OS thread. The unshare call affects only the current thread[2][3]. Even then, you have to be careful not to spawn any new goroutines[4]. For this reason, parts of runc are currently written in C (you could technically implement it in pure Go, but the maintainers believe it's easier to reason about the C implementation). - The container runtime has to reexec itself from a copy of itself in a memfd to prevent the container from writing to /proc/self/exe[5][6]. - Various race conditions and symlink attacks during container setup[7][8]. - Some parts of the container initialization have to be done after switching to the new rootfs, which is attacker-controlled territory[9][10]. - ... and plenty of other gotchas, the runc code is full of comments that explain why things have to be done in particular ways. Obviously, Gocker is an experiment and does none of these things, and you shouldn't run it on anything that you care about :) Sometimes things are complex for a reason. [1]: https://github.com/opencontainers/runc https://github.com/opencontainers/runc [2]: https://golang.org/doc/go1.10#runtime https://golang.org/doc/go1.10#runtime [3]: https://github.com/golang/go/issues/20676 https://github.com/golang/go/issues/20676 [4]: https://www.weave.works/blog/linux-namespaces-golang-followup https://www.weave.works/blog/linux-namespaces-golang-followu... [5]: https://github.com/opencontainers/runc/pull/1984 https://github.com/opencontainers/runc/pull/1984 [6]: https://github.com/opencontainers/runc/commit/0a8e4117e7f715d5fbeef398405813ce8e88558b https://github.com/opencontainers/runc/commit/0a8e4117e7f715... [7]: https://github.com/opencontainers/runc/issues?q=race+condition https://github.com/opencontainers/runc/issues?q=race+conditi... [8]: https://github.com/cyphar/filepath-securejoin https://github.com/cyphar/filepath-securejoin [9]: https://github.com/opencontainers/runc/pull/2207 https://github.com/opencontainers/runc/pull/2207 [10]: https://github.com/opencontainers/runc/issues/2128 https://github.com/opencontainers/runc/issues/2128